Security Posture

Microsoft 365 Security Assessment Checklist

A Microsoft 365 security assessment is only as complete as the list of things it checks. Secure Score alone misses Conditional Access exclusions, standing admin roles, and anything outside the tenant. This is the checklist to work through, in order, for a tenant you are onboarding, auditing, or inheriting from someone else.

1. Identity and Conditional Access

Start here, because identity is where most compromise starts and where the rest of the assessment gets its context. Check MFA registration separately from enforcement — a tenant can have MFA available while a meaningful share of accounts have never registered a strong method. Review Conditional Access policy coverage and every exclusion, not just whether policies exist: the risk usually sits in the gap between policies, not in any single one.

Then check privileged role assignments against how many people actually need them, whether legacy authentication protocols such as IMAP, POP, or SMTP AUTH are still reachable, and whether a break-glass account exists, is excluded from the policies it needs to survive, and has not drifted into everyday use. The full per-tenant version of this section, with the specific gaps MSPs find most often, is in Entra ID & Conditional Access review for MSPs.

2. Secure Score and Microsoft controls

Record the current score and read the improvement actions behind it, not just the percentage. Actions can be marked planned, resolved through a third party, or risk-accepted — useful for tracking, but it means a score can rise without the underlying control actually changing. Treat the number as one input to the assessment, and the improvement-action list as a set of candidate findings to verify rather than accept at face value. See Microsoft Secure Score for MSPs for what the score does and does not measure.

3. Defender, sharing, and admin configuration

Where the customer is licensed for Defender for Endpoint, check device posture and open alerts. Review external sharing settings for SharePoint and OneDrive — what an external user can access and whether sharing links expire. Confirm which admin roles are standing versus time-bound, since a permanent Global Administrator that also holds a mailbox and a license is a phishing target with tenant-wide rights attached.

4. The external footprint

Everything above lives inside the Microsoft 365 admin center. A complete assessment also covers what sits outside the tenant: the customer's domains, DNS and email authentication records, TLS certificate status, and any services exposed on the public internet. This is the part a tenant-only review skips entirely, because it is internet-scoped rather than tenant-scoped. See External attack surface monitoring for what discovery should check here.

Turning the checklist into a report

A checklist is only useful once the findings are ranked and handed to someone. Order results by severity so the customer conversation starts with the critical few, not a wall of settings. See Microsoft 365 security assessment for how the full review comes together, and security reporting for turning it into a customer-ready document.

The assessment is the baseline, not the last review

Every item on this checklist describes the tenant on the day it was checked and starts decaying from there. Treat this run as the baseline every later review compares against, then re-run the same checks on a schedule so a disabled policy or a new exclusion becomes a finding instead of a surprise. See Microsoft 365 security posture for the ongoing side of this, and MSP security monitoring: what to track across every customer tenant for the signals worth checking between full assessments.

Frequently asked questions

Learn more

Run this checklist as a free assessment

Connect one Microsoft 365 tenant with read-only access and get real findings against this checklist, not sample data.